MyDr A.I CyberSecurity Scoring
MyDr
Company Information
Website:https://pro.mydr.pl/
Employees number:55
Number of followers:2,036
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:mydr.pl
MyDr Risk Score (AI oriented)
Between 0 and 549
MyDrTechnology, Information and Internet
Updated:
28/09/2026
28/09/2026
527/1000
Critical
C
MyDr Global Score (TPRM)
xxxx
MyDrTechnology, Information and Internet
Score locked

MyDrCritical
Current Score
527C (CRITICAL)
01000
3 incidents
-107.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
528
SEPTEMBER 2026
623
Breach
09 Sep 2026 • MyDr
MyDr and Qbusoft: Cyberattack on Polish medical software provider exposes patient data
Polish Healthcare Software Provider Qbusoft Hit by SQL Injection Attack, Exposing Patient Data
524
CRITICAL-99
MYDALE1790605448
Polish Healthcare Software Provider Qbusoft Hit by SQL Injection Attack, Exposing Patient Data
Hackers breached Qbusoft, a Polish healthcare software provider, in late August by exploiting an SQL injection vulnerability in its Medyc platform a cloud-based system used for electronic medical records, prescriptions, and patient management. The attack, detected on September 9, resulted in the theft of personal data, including names, national identification (PESEL) numbers, addresses, phone numbers, and email addresses. While Qbusoft has not confirmed the exfiltration of medical records, an affected healthcare provider the Addiction and Psychiatric Treatment Center in Inowrocław reported that attackers likely accessed hospital treatment records and discharge summaries from its Day Treatment Unit, covering patients treated between July 2024 and August 2026.
The breach occurred when an unauthorized actor exploited the SQL injection flaw to extract an encrypted database archive before transferring it outside Qbusoft’s systems. Though some data was encrypted, Qbusoft warned that decryption was probable. The company patched the vulnerability on September 9, restricted database permissions, rotated credentials, and enhanced monitoring. However, it has faced repeated attack attempts in recent weeks, leading to temporary service disruptions.
Polish authorities, including the Central Bureau for Combating Cybercrime and the national data protection authority, are investigating the incident. Digital Affairs Minister Krzysztof Gawkowski criticized Qbusoft for failing to report the breach to CERT Polska or the healthcare sector’s incident response team, emphasizing that such delays increase risks to citizens. An audit of Qbusoft has been ordered, and the government is drafting regulations to strengthen healthcare data protections, including mandatory security certifications and stricter controls on private companies handling medical information.
The Medyc breach follows a larger incident involving MyDr, another Polish healthcare software provider, which potentially exposed data on 19 million individuals and 12,000 organizations. The Inowrocław treatment center was affected by both breaches. Cybersecurity publication Zaufana Trzecia Strona reported that a threat actor linked to the MyDr attack using the alias "fingerprint" claimed responsibility for the Medyc breach, alleging access to 5 million patient records and 8 million private images. The group stated their motive was to expose weak cybersecurity rather than financial gain, though Polish authorities have not confirmed these claims or publicly attributed the attack. No stolen data has been released.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
737
Breach
12 Aug 2026 • MyDr
MyDr and Ministry of Digital Affairs: A massive data breach in Poland affected nearly 19 million people
Massive Data Leak Exposes Medical Records of Nearly 19 Million Poles
621
CRITICAL-116
MYDMIN1786574278
Massive Data Leak Exposes Medical Records of Nearly 19 Million Poles
Poland’s Minister of Digital Affairs, Krzysztof Gawkowski, revealed on August 12 that a significant data breach in the MyDr medical system may have compromised the personal and health information of nearly 19 million people. The system, used by doctors and healthcare institutions, contained sensitive data, including prescriptions, appointment schedules, medication records, and patient-submitted documents.
The breach involved the theft of over 2 terabytes of data, comprising 19 million records that could potentially be linked to individuals. Authorities have not identified signs of an external cyberattack, suggesting the leak may have resulted from human error, system failure, sabotage, or negligence by the company operating MyDr.
Approximately 12,000 medical facilities using the system have been notified, though operations continue as usual. The Central Cybercrime Bureau is leading the investigation, while the Ministry of Digital Affairs has advised affected citizens to verify whether their data was exposed and consider blocking their PESEL (national identification) numbers if necessary. The full scope and impact of the breach remain under assessment.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
737
JUNE 2026
736
MAY 2026
736
APRIL 2026
735
MARCH 2026
735
FEBRUARY 2026
734
JANUARY 2026
733
DECEMBER 2025
733
NOVEMBER 2025
732
APRIL 2024
766
Cyber Attack
01 Apr 2024 • MyDr
MyDr: Poland probes MyDr healthcare software breach potentially affecting 19 million people
Polish Healthcare Software Provider MyDr Hit by Cyberattack Affecting Millions
715
CRITICAL-51
MYD1786983836
Polish Healthcare Software Provider MyDr Hit by Cyberattack Affecting Millions
Polish authorities are investigating a cyberattack on MyDr, a healthcare software provider, that may have exposed data belonging to nearly 19 million people and over 12,000 medical facilities. The company, which supplies software to doctors, clinics, and healthcare providers, confirmed on Friday that it had mitigated the incident and implemented additional security measures but did not disclose how attackers gained access.
The breach, described as "external, intentional criminal activity," involved unauthorized access to historical data stored in MyDr’s systems up to April 2024. While the company found no evidence that the stolen data had been published, Polish cybersecurity media reported that unidentified threat actors had contacted a local outlet, claiming responsibility and providing a screenshot of data linked to a prominent politician. The alleged stolen material may include names, dates of birth, identification numbers, prescription details, and medical records, though these claims remain unverified.
MyDr’s software integrates with Poland’s nationwide e-health platform (P1), which supports electronic prescriptions and referrals. As a precaution, the Polish e-Health Center is replacing digital certificates used by medical systems to connect to P1, though officials stated there was no evidence the certificates were compromised in the attack. Health Minister Jolanta Sobierańska-Grenda assured that the incident posed no threat to Poland’s public healthcare systems, and P1 remained secure.
The Polish Personal Data Protection Office plans to inspect MyDr, while security agencies work to identify the attackers. Digital Affairs Minister Krzysztof Gawkowski warned that the company could face legal consequences if found negligent in protecting its systems. The attack has not been attributed to any specific threat actor.
This incident follows another recent cyberattack on Polish convenience store chain Żabka, where attackers breached internal systems via a third-party contractor. No connection between the two incidents has been established.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MyDr ??
What was MyDr's A.I Rankiteo Cyber Score in September 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in August 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in July 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in June 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in May 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in April 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in March 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in February 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in January 2026 ??
What was MyDr's A.I Rankiteo Cyber Score in December 2025 ??
What was MyDr's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on MyDr's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MyDr ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MyDr's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?